CVE-2014-9938
Published: 19 March 2017
contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.
Priority
CVSS 3 base score: 8.8
Notes
Author | Note |
---|---|
mdeslaur | PoC: https://github.com/njhartwell/pw3nage only affects 1.8.1+ |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9938
- https://ubuntu.com/security/notices/USN-3243-1
- NVD
- Launchpad
- Debian